Disclaimer: This website requires Please enable JavaScript in your browser settings for the best experience.

HomeDev GuideAPI Reference
Dev GuideAPI ReferenceLegal TermsDev CommunityOptimizely AcademySubmit a ticketLog In
Dev Guide

Optimizely Customized Commerce

Describes the GDRP guidelines for Optimizely Customized Commerce.

Collect data

  • Contact Data – Ecommerce customers register or are registered by the Customer Service Department.
  • Order Data – Ecommerce customers complete a purchase or are registered by the Customer Service Department.
  • Shopping Cart – Ecommerce customers add items to their shopping cart. This is viewable by different default admin roles in Commerce Manager.

📘

Note

Avoid storing this data in other custom locations, or you will be responsible for keeping track of PII data that could be susceptible to GDPR compliance.

Any page requesting input of PII data should be using HTTPS protocol, TLS 1.2 or later.

Ask for consent

You should, by default, enable double opt-in, informing the end user of their rights and ask for consent. An example of double opt-in is available in the Optimizely Customized Commerce reference site Quicksilver.

Store data

On-premises installations require encryption of your database instance TDE and encryption at rest.

In Optimizely DXP, TDE is enabled by default. See also Store data.

Use data

You should inform the end user about how the user data is used.

Fetch data

You should be able to fetch most data types by querying the Customized Commerce database. You can request the Managed Services team to fetch data about a user in cases where you cannot fetch the data yourself.

Delete data

You should be able to delete most data types by querying the Optimizely Customized Commerce database. You can make a request to the Managed Services team for deleting data in cases where you cannot delete the data yourself.